CVE
CVE-2026-57148
0field notes · 1digest CVSS 9.8
The verdict
PraisonAI's platform ships with a hardcoded default JWT signing key ('dev-secret-change-me') that's active whenever the PLATFORM_JWT_SECRET environment variable isn't set. Since the platform also defaults to dev mode, an unauthenticated attacker can forge a valid JWT for any user or workspace owner and impersonate them. If you deployed PraisonAI without explicitly setting that secret, you're wide open.
Patch urgency · Patch immediately
Daily digests